๐Ÿ” CVE Alert

CVE-2026-55156

MEDIUM 5.3

Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in token-optimizer-mcp exposes /api/session-summary and /api/session-events with no authentication middleware โ€” any network-accessible client can reach them without credentials. Both handlers concatenate the caller-supplied sessionId query parameter directly into a filesystem path via path.join, and Node.js normalizes .. segments at resolution time, allowing an unauthenticated attacker to read any .jsonl file reachable from the server's filesystem. This issue has been patched in version 5.1.0.

CWE CWE-22
Vendor ooples
Product token-optimizer-mcp
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for ooples token-optimizer-mcp

Be the first to know when new medium vulnerabilities affecting ooples token-optimizer-mcp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

ooples / token-optimizer-mcp
< 5.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ooples/token-optimizer-mcp/security/advisories/GHSA-76pc-mqxp-3rq5 github.com: https://github.com/ooples/token-optimizer-mcp/commit/b4ee96dac799cbfba0a9f9c17844ce9d613cbcc7 github.com: https://github.com/ooples/token-optimizer-mcp/releases/tag/v5.1.0